The risk assessment is the foundation of every AML/CFT compliance programme. In both New Zealand and Australia it is the document on which everything else is built: the customer due diligence model, the monitoring rules, the escalation pathways, and ultimately the defensibility of the entire framework. Yet the two regimes arrive at this common starting point from different statutory architectures, and the gap between them has widened in 2026 as Australia’s reformed regime takes effect.
This brief sets out, for compliance officers and advisers operating on both sides of the Tasman, how the risk assessment obligation is framed in each jurisdiction, where the requirements align, and where the practical differences matter. Throughout, we distinguish between what is a legal requirement, what is regulatory expectation, and what is supervisory guidance or best practice — a distinction that is easily lost but central to a defensible position.
The statutory obligation
New Zealand s 58, AML/CFT Act 2009
In New Zealand, the obligation sits in section 58 of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009. Before conducting customer due diligence or establishing an AML/CFT programme, a reporting entity must first assess the money laundering and terrorism financing risk it may reasonably expect to face in the course of its business. The risk assessment is, in the words of all three supervisors, the first step a business must take, and the AML/CFT programme required under s 56 must be based on it.
Section 58(2) directs the reporting entity to have regard to a defined set of factors — the nature, size and complexity of the business; the products and services it offers; the methods by which it delivers them; the types of customers it deals with; the countries it deals with; and the institutions it deals with. The Department of Internal Affairs has been explicit that a generic, sector-level template will not satisfy section 58: the assessment must engage with the entity’s own business.
New Zealand’s obligation addresses two risks — money laundering and terrorism financing. Proliferation financing is not a standalone limb of the section 58 assessment in the way it is in the reformed Australian regime.
Australia s 26C, AML/CTF Act 2006 (reformed)
Australia’s risk assessment obligation was, until recently, embedded in the Part A programme requirements rather than expressed as a freestanding duty. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) changed that. From 31 March 2026 for existing reporting entities, and 1 July 2026 for newly regulated “Tranche 2” entities (lawyers, accountants, real estate professionals and dealers in precious metals and stones), the reformed Act sets out a distinct ML/TF risk assessment obligation in section 26C.
Under section 26C, a reporting entity must assess the risks of money laundering, terrorism financing and proliferation financing (ML/TF/PF) that it may reasonably face in providing its designated services. The assessment must be documented and in place before the entity begins providing a designated service, and it must have regard to the nature, size and complexity of the business and a defined set of risk factors — designated services and the methods of delivery (including new and emerging technologies), customer types, and the foreign jurisdictions the entity deals with.
Crucially, the reform abolishes the old Part A / Part B split. The risk assessment and the AML/CTF policies together now constitute a single, outcomes-focused AML/CTF program under s 26B, with the risk assessment expressly the first component that shapes the policies.
Side-by-side comparison
The comparison below sets out the core features of the risk assessment obligation in each jurisdiction. Legal requirements are stated as such; where a point reflects supervisory expectation or guidance rather than the statute, this is flagged.
Risk assessment obligation · feature comparison
Note: review-cycle and three-year points on the Australian side reflect the Act read with AUSTRAC guidance and the Rules; the statute expresses the trigger as significant change rather than a fixed clock. New Zealand’s three-yearly audit cadence is the supervisory default position, subject to direction.
Where the two regimes align
Despite the architectural differences, the underlying logic is shared. Both regimes:
- Put risk first. The risk assessment is the precondition for everything else, and the compliance programme must flow from it rather than sit alongside it.
- Adopt a risk-based approach. Both supervisors expect the depth of CDD, the intensity of monitoring and the frequency of review to be calibrated to assessed risk, not applied uniformly.
- Reject generic templates. The DIA’s position that sector-level content alone will not satisfy section 58 mirrors AUSTRAC’s expectation that the assessment must reflect the entity’s actual designated services and customer base.
- Are FATF-aligned. Both frameworks are built to meet the FATF Recommendations, and both jurisdictions face FATF mutual evaluation pressure — Australia’s reform timetable is driven in part by its 2026 evaluation.
- Require documentation and governance. In each case the assessment must be written, kept current, and capable of withstanding regulatory scrutiny; senior management and board visibility is expected.
Where they diverge — and why it matters
Proliferation financing
The most consequential divergence is scope. Australia’s reformed assessment must address proliferation financing as a distinct risk, consistent with the updated FATF standards. New Zealand’s section 58 remains framed around money laundering and terrorism financing. A trans-Tasman group cannot simply lift its New Zealand risk assessment across the Tasman; the Australian document must explicitly engage with PF risk, sanctions-evasion typologies and the relevant designated services.
The designated-services lens
Australia anchors the assessment to designated services — a defined list of captured activities. A reporting entity assesses risk service by service, and an activity that is not a designated service falls outside the obligation. New Zealand’s section 58 is framed more around the business as a whole and the products and services it offers. For Tranche 2 entities in particular, the first analytical task is determining which of their activities are designated services at all — a threshold question that has no direct New Zealand analogue.
Review cadence and triggers
New Zealand does not fix a statutory review interval for the risk assessment itself; the discipline comes through the three-yearly independent audit under s 59A and supervisory expectation of regular review. Australia’s regime is more explicit about review triggers, supplemented by AUSTRAC guidance recommending periodic review (currently at least every three years). Entities operating in both jurisdictions should adopt the more conservative position and treat regular, triggered review as mandatory in both.
Programme architecture
The abolition of the Part A / Part B distinction in Australia brings its structure closer to New Zealand’s single-programme model, but the reform goes further by making non-compliance with an entity’s own AML/CTF policies a civil penalty matter. The practical effect is that a poorly drafted or aspirational policy is now a liability rather than a cushion.
A poorly drafted or aspirational policy is now a liability rather than a cushion — a point that argues against “zero-tolerance” drafting in favour of proportionate, achievable controls.
Transition risk in Australia
Finally, timing. Australia is mid-transition. Existing reporting entities are expected to have refreshed their enterprise-wide ML/TF/PF risk assessment by 31 March 2026; Tranche 2 entities by 1 July 2026. AUSTRAC has signalled that it expects documented implementation plans and sustained progress rather than perfect compliance from day one — but it has been equally clear that failing to manage ML/TF risk is a serious concern now and will remain so after commencement. For advisers, the live risk is treating an implementation plan as a substitute for the assessment rather than a bridge to it.
Practical takeaways for trans-Tasman practitioners
- Do not port a risk assessment across the Tasman unchanged. The PF limb, the designated-services lens and the different prescribed factors mean each document must be purpose-built for its jurisdiction.
- Adopt the more conservative review cadence in both. Treating the assessment as a living document — reviewed on every material change, and at least on a fixed cycle — satisfies both regimes and is defensible to either supervisor.
- Mind the policy-liability shift in Australia. Because policy breaches are now civil penalty matters, risk-appetite and control commitments should be proportionate and operationally achievable.
- Keep the requirement hierarchy visible. Distinguish in the document itself between statutory obligations, supervisory expectations and best practice, so a reviewer can see the basis for each control.
- Verify against primary sources. Both regimes are in flux — the AML/CTF Rules 2025 and the 2026 amendment and transitional rules in Australia, and ongoing NZ guidance updates. Confirm the current text before finalising any deliverable.
In a defensible document, practitioners should distinguish between:
- Statutory obligations (mandatory).
- Subordinate legislation (Rules or Regulations).
- Approved Codes of Practice (where applicable).
- Supervisory guidance.
- Regulatory expectations reflected in enforcement action and thematic reviews.